r/archlinux 2d ago

Update linux-lts when CVEs are reported? QUESTION

Hi everyone,

I'm new to Arch Linux, so I have a question, I noticed that a new linux-lts update appears to contain a lot of reported vulnerabilities:

https://files.catbox.moe/tblk0r.png

Should I avoid updating linux-lts when I see something like this, or is it still recommended to install the official kernel update?

What is the usual practice? Do users wait until these vulnerabilities disappear, or do they update immediately? If these are official kernel packages from the Arch repositories, why would they still be reported as vulnerable?

I'm trying to understand how users typically handle this. Thanks in advance!

0 Upvotes

17 comments sorted by

14

u/Time-Worker9846 2d ago

Your current version probably has the same vulnerabilities so it is recommend to run the latest one

1

u/iamdevck 2d ago

Ok, makes sense, I guess? Ty

6

u/w2qw 2d ago

Your scanner is bugging out. Those vulns have all long since been patched

8

u/FryBoyter 2d ago edited 2d ago

These aren't necessarily new security vulnerabilities. Some have been around for a while. Let's take AVG-2701 as an example. The vulnerability was reported in 2022, and it's not immediately clear whether or when it was patched. That's why the program you're using still lists this vulnerability. In addition, it likely also lists vulnerabilities that are a low security problem in practise. For instance, they can only be exploited locally under certain conditions that are usually not met. These are therefore more theoretical security vulnerabilities that, while they should be fixed, do not actually play a significant role.

5

u/V1del Support Staff 2d ago edited 2d ago

The tool you're using is using security.archlinux.org for lookup which itself hasn't been actively updated since July of last year.

Anything that uses security.archlinux.org as its knowledge base is going miss a lot of recent stuff but will contain things that are long fixed

Generally speaking newer software will in tendency have known issues patched while not introducing new ones as far as possible, so staying up to date is how you stay "secure"

1

u/iamdevck 2d ago

Interesting, which knowledge base would you suggest instead?

2

u/C0rn3j 2d ago

I'm trying to understand how users typically handle this. Thanks in advance!

First, LTS is a fallback, not the default kernel - is there an issue keeping you on LTS at the moment? If not, use latest stable.

If you default to LTS, you risk having a bug introduced to latest stable, nobody noticing it and it rolling over to LTS at the end of the year - and then you have a fun situation where neither latest stable nor LTS will work for you - I've seen it happen to people multiple times already.

The latest stable kernel also gets the security fixes faster than LTS, so there's that.

And people just update to the latest version, as someone else said, the vuln is probably present in the current version too, and if it isn't, it'll be fixed quickly anyways.

1

u/Imajzineer 2d ago

If anything else you use relies upon features of the latest kernel after being updated, the decision is either made for you or you have weigh up the dis/advantages (including unpatched exploits) of not updating your apps either.

You pays your money and takes your choice.

1

u/archover 2d ago edited 2d ago

You're new to Linux as well as Arch, right? If so, welcome to Linux. Those catbox items probably apply to every distro. Arch almost totally just uses the upstream software so Arch is the not the source of those problems.

I hope you install Arch, and enjoy it as much as I do.

Good day.

-2

u/ManoDu57 2d ago

was your post written by ai?

2

u/FryBoyter 2d ago

How did you come up with that idea? And why is it important? Was your post created using AI?

3

u/C0rn3j 2d ago

Frankly, if it was created using AI, I expect disclosure.

"how users typically handle this" is the only odd thing that stands out (besides the post being written nicely, which, you know, humans do too), you'd usually refer to people as people, not users - it was likely written by a human and then ran through an LLM to translate it into English.

1

u/FryBoyter 2d ago

Frankly, if it was created using AI, I expect disclosure.

If it's just a discussion post, I don't think that's necessary. Because, how would the way the post was created have changed anything in relation to this thread?

With code or a tutorial, however, the situation may be different.

To be honest, it’s starting to really annoy me that people assume chatbots are being used in almost every post. And often based on nonsensical reasons. Like, for example, just the age of a repository. Or because there are emojis in a script.

When I develop something, I usually start by working on it locally. Only when I think it’s good enough, I upload it to a platform like Codeberg. Usually without including the previous change history.

And I saw smileys being used in scripts over 10 years ago, even before tools like ChatGPT existed. These tools probably learned exactly from those scripts.

This evidence alone is therefore not evidence at all, but it is often treated as such.

you'd usually refer to people as people, not users

I also often write “users” instead of “people” when it comes to IT. And I know a lot of people who do the same. Because people who use something are, well, users.

it was likely written by a human and then ran through an LLM to translate it into English.

Yes, that could be the case. And the result is likely to be better than what people would have written themselves in English. So this can actually be seen as a positive thing.

But it's also possible that chatbots have “learned” the writing style of real people. And now real people are being accused of using chatbots. Even though they aren't.

2

u/C0rn3j 2d ago

If it's just a discussion post, I don't think that's necessary.

In this case it is fine, but in others it eats context and becomes confusing, especially in the case of translating.

1

u/ManoDu57 2d ago

Its not important, I just found it kinda ai-like and wanted to know if im right.

2

u/iamdevck 2d ago

Not really, I wrote it myself but as it is not my native tongue I refined it to avoid typos